Silver Fox
Threat actor targeting Japanese businesses with spearphishing campaigns, deploying ValleyRAT remote access trojan. Active in tax season campaigns against Japanese manufacturers.
Attribution signal
?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low2.5
Low signal strength
Mentions4
Sources2
High conf.3
Last seenMay 2026
First observed
—
Last active
—
Origin
China
Aliases
1
Techniques
0
Campaigns
0
China
TargetsManufacturingTechnology
RegionsJapanAsia
Attribution signals
4 mentions · 2 sources#1high
TTP matchMalware
securelist
May 2026
#2detailedhigh
MalwareVictimology
checkpoint
May 2026
"Researchers detailed a Silver Fox campaign targeting organizations in India and Russia with tax-themed phishing emails."
Campaign: Silver Fox
#3exploitshigh
Malware
wechat-qax-ti
May 2026
"Silver Fox exploits new ABCDoor backdoor to attack Russia and India"
#4unspecified
TTP matchMalwareVictimology
eset
May 2026
Campaign: Japanese tax season spearphishing campaign 2026
Hedge terms observed
detailedexploits